Standing, once: Switzerland is not in the European Union, the GDPR is not the operative instrument, and the German, French and Italian texts of the Act are the binding ones. Fedlex publishes an English translation, but English is not an official language of the Confederation and it has no legal force. Where anything below diverges from the binding text, the binding text governs.
What triggers the duty under Art. 22 revFADP?
Art. 22 para. 1 requires the controller to carry out an impact assessment in advance where the intended processing is likely to entail a high risk to the personality or fundamental rights of the data subject. The word in advance is doing work: the assessment precedes go-live; it does not document it afterwards.
Para. 2 explains how that risk is judged — from the nature, scope, circumstances and purpose of the processing, in particular where new technologies are used — and names two cases: large-scale processing of sensitive personal data and systematic extensive monitoring of public areas.
Both are illustrations, not a closed list. A reader who concludes that nothing outside health data and video surveillance is caught has read the provision too narrowly. The converse error is as common: calling an API on a language model does not by itself establish a high risk. What decides is the processing — which personal data, at what scale, for what purpose, with what effect on the person.
So Art. 22 first triggers an examination, not necessarily a full assessment, and the triage fits on one page per application. The FDPIC's update of 8 May 2025 supports treating it as routine: the FADP is technology-neutral and directly applicable to AI-supported processing, and the FDPIC names an impact assessment for high-risk applications alongside transparency about purpose, functioning and data sources, human review of automated decisions, the right to know whether one is speaking to a machine, and recognisability of deepfakes.
Why is the 250-employee figure a trap?
Because it belongs to a different obligation. The threshold sits in Art. 24 of the Data Protection Ordinance, SR 235.11, and relieves only the duty to keep a record of processing activities under Art. 12 FADP. Art. 22 has no size threshold at all.
The record exemption carries its own exception, and that exception is the real subject. Private-law bodies employing fewer than 250 people on 1 January of a year are released unless sensitive personal data are processed on a large scale, or high-risk profiling is carried out. A model rating or classifying people — creditworthiness, fraud probability, attrition risk, suitability — can constitute high-risk profiling, and where it does a thirty-person company owes the same record as a group. Size does not decide; what the system does to people decides.
| Criterion | Record — Art. 12 FADP, Art. 24 DPO | Impact assessment — Art. 22 FADP |
|---|---|---|
| Trigger | Any processing activity by a controller or processor | Processing likely to entail a high risk to personality or fundamental rights |
| Size threshold | Exemption below 250 employees, lost on large-scale sensitive data or high-risk profiling | None |
| Route out | Art. 24 DPO only | Art. 22 para. 5: certification under Art. 13, or a code of conduct under Art. 11 |
| External consultation | — | High residual risk: FDPIC under Art. 23, position within two months, extendable by one; a private controller may consult its own data protection adviser instead |
| Effect of omission | Not punishable in itself; relevance only indirectly, through an FDPIC ruling and Art. 63 FADP | |
Can a Swiss controller skip the assessment altogether?
Art. 22 para. 5 opens an exit that few controllers use and most should test before commissioning a full assessment: a private controller may dispense with the assessment where it uses a certified system, product or service under Art. 13 FADP, or complies with a code of conduct under Art. 11 FADP.
Its limit is easy to miss. The certification or the code must cover the processing in question. Subscribing to a model interface from a certified provider does not make the application built on top of it certified — that application has its own data sources, its own purposes and its own decision thresholds, and those are what the assessment would examine.
Which group entity owes the assessment?
Art. 22 places the duty on the controller — in a group, usually the Swiss operating entity whose customers, employees or applicants are the data subjects, not the platform team running the model and not the group function that bought it. A shared AI service used by five entities can require five triage decisions, because the processing, the purposes and the affected populations differ.
For a vendor selling into Switzerland the position is the mirror image, and worth stating to prospects: acting as a processor, the vendor owes no Art. 22 assessment. Its Swiss customer does — and cannot complete it without the vendor, because the assessment needs the model and configuration version in force at the time of a decision, the data sources, the drift-monitoring arrangements and the means by which a single decision can be reconstructed later. A vendor that cannot supply those turns its customer's assessment into a set of assumptions, which is a procurement obstacle long before it is a legal one.
A controller established abroad with no Swiss establishment is not outside the Act either. Art. 14 requires such a private controller to designate a representative in Switzerland where four cumulative conditions are met: processing connected with offering goods or services in Switzerland or monitoring behaviour there, on a large scale, on a regular basis, and posing a high risk to data subjects. Narrower than its GDPR analogue — but its existence confirms the Act reaches beyond Swiss-established entities. Scope in full under Art. 21 and automated decisions.
Two further boundaries: a Swiss entity offering goods or services to, or monitoring, people in the EU can fall within the GDPR on the Regulation's own terms; and a Swiss firm placing an AI system on the Union market, or whose output is intended to be used there, is within the EU AI Act — Article 2 of Regulation (EU) 2024/1689 applies irrespective of establishment, and an Art. 22 assessment does not discharge it. A purely domestic deployment faces neither.
What does an assessment for an agentic system have to contain?
Beyond the usual content — description of the processing, assessment of the risks, measures envisaged — a system that acts on its own needs three sections that standard templates omit.
The Art. 21 analysis
Does the system produce automated individual decisions, and if so does the exception in Art. 21 para. 3 lit. a apply? It applies only where the data subject's request is granted, so the cases where the agent says no — refused application, withheld activation, negative assessment — remain fully within the duty to inform and the right to review by a natural person. This is the commonest gap in templates imported from a GDPR programme, which treat the whole contract case as covered.
Who qualifies the residual risk
Art. 23 requires consultation of the FDPIC where a high residual risk remains despite the measures taken; it states its position within two months, extendable by one, and a private controller may instead consult its own data protection adviser. A serious assessment names who is competent to declare the residual risk acceptable, and dates that judgement. Two months is a project milestone, not something absorbed in the last week before launch.
How a single decision will be reconstructed
This section is missing from almost every template and matters most. The review right in Art. 21 para. 2 presupposes it can be established afterwards what the system did, on which data, with which model and configuration version, at what time, and on whose authorisation. Without that chain the promised review cannot be carried out — only repeated, which is a different thing, because re-running the agent produces a new decision rather than an explanation of the old one. Name the evidential route; do not assert that logging exists. See traceability for AI agents and audit trail requirements for AI agents.
What does an omitted assessment actually cost?
Nothing directly, and that is the point most often reported wrongly in English. First, Art. 60 to 63 FADP are criminal provisions imposing fines on natural persons of up to CHF 250,000 — not administrative fines on undertakings. Under Art. 64 para. 2 the company may be ordered to pay instead, but only where a fine of no more than CHF 50,000 is in issue and identifying those responsible would require disproportionate investigative measures. Second, the FDPIC does not levy these fines: it issues rulings (Verfügungen / décisions), and fines are pronounced by the cantonal criminal prosecution authorities. Third, the omitted assessment is not in the catalogue at all — nor is a missing record (Art. 12) or an unreported breach (Art. 24). Each becomes relevant only indirectly, through an FDPIC ruling and Art. 63.
Art. 61 does capture three breaches of due diligence, and only when intentional: unlawful disclosure abroad (Art. 16 and 17); engaging a processor without meeting Art. 9 para. 1 and 2; and failure to observe the minimum data security requirements of Art. 8 para. 3. That third route — not a missing register — is how logging and security gaps become criminally relevant.
None of this makes the assessment optional; it relocates the argument. It is produced not because a fine threatens but because it is the only structured way to judge the duties that are penalised — foreign disclosure, processor engagement, data security — before the system is live. Filed in the register of corrections.
Where does the FINMA inventory fit?
For a supervised institution, FINMA Guidance 08/2024 of 18 December 2024 expects an inventory of AI applications with a risk classification on a broad definition of AI, and an independent review separating development from validation. That is the same raw material the Art. 22 triage needs: one inventory with a column for the FINMA classification and a column for the triage conclusion serves both, whereas two parallel registers diverge within six months.
The status of that document is worth stating correctly, because English coverage regularly gets it wrong: it is a supervisory communication — Aufsichtsmitteilung, communication sur la surveillance, FINMA Guidance in FINMA's own English — expressly not a circular and not binding regulation. The binding instruments are FINMA Circulars 2023/1 and 2018/3. See FINMA Guidance 08/2024 in full.
Implementation sequence
- Inventory AI-supported processing on a broad definition, including models nobody internally calls AI, and name the Swiss controller for each entry.
- Document the Art. 22 triage per application: reasoned conclusion, date, owner — including where the conclusion is negative.
- Test the Art. 22 para. 5 exemption first, confirming the certification or code covers the actual processing.
- Settle the record duty separately: high-risk profiling removes the 250-employee exemption.
- Include the Art. 21 analysis, asking expressly whether the outcome can be a refusal.
- Name who qualifies the residual risk, and put the Art. 23 two-month period in the project schedule.
- Describe how a single decision is reconstructed, and set thresholds at which an automated action needs human release before it executes — see approving AI actions before execution and governed workflow automation.
- Re-open the assessment on a material change of model, data source or purpose.
In practice
BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, which is what the reconstruction section of an assessment has to be able to point at. BarzelOps runs the cross-system workflow with durable state, approval checkpoints and tenant isolation, so a shared model estate still produces evidence attributable to one Swiss controller.
Frequently asked questions
When is an impact assessment mandatory?
Where the intended processing is likely to entail a high risk to personality or fundamental rights (Art. 22 para. 1). Para. 2 names the use of new technologies expressly, citing large-scale sensitive data and systematic extensive monitoring of public areas as examples.
Does the 250-employee threshold exempt a company?
No. That figure sits in Art. 24 of the Data Protection Ordinance and concerns only the record of processing activities. Art. 22 has no size threshold.
Can the assessment be skipped, and what if a high residual risk remains?
Art. 22 para. 5 allows it where a certified system, product or service under Art. 13, or a code of conduct under Art. 11, covers the processing in question — not merely the underlying product. Where a high residual risk remains, Art. 23 requires consultation of the FDPIC, which states its position within two months, extendable by one; a private controller may instead consult its own data protection adviser.
What is the fine for a missing assessment?
There is none. The omission is not punishable in itself; relevance arises only indirectly through an FDPIC ruling and Art. 63. The FDPIC issues rulings and does not levy fines.
Does re-running the model count as review?
No. It produces a new decision. Art. 21 para. 2 presupposes the original decision can be reconstructed from its inputs, model or rule version and timestamp.
Where this leads
The impact assessment is not a document produced for an authority. It is the moment an organisation writes down what a system will do to people, before it does it. Its quality is measurable by one testable question: six months from now, can anyone establish which data and which model version a given decision rested on? While the answer is no, the human review it promises remains an intention.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
In forceRevised FADP in force since 1 September 2023
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- Automated individual decisions under Art. 21 revFADP
- FINMA Guidance 08/2024: what supervised institutions implement
- Cyber incident reporting: 24 hours to the NCSC
- Traceability for AI agents in a Swiss deployment
- AI governance — the complete guide
- Glossary of regulatory and technical terms
Sources
- Federal Act on Data Protection (FADP; DSG / LPD), SR 235.1, Art. 8, 11, 12, 13, 21, 22, 23 and 60 to 64 — binding texts: German, French; English translation, fedlex.admin.ch.
- Ordinance on Data Protection (DSV / OPDo), SR 235.11, Art. 24 — German, French, fedlex.admin.ch.
- FDPIC, Update: current data protection legislation is directly applicable to AI, 8 May 2025.
- FDPIC, Obligation to appoint a representative under Article 14 FADP.
- Swiss Federal Council, media release of 12 February 2025 on the regulatory approach to artificial intelligence.
- FINMA, FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence, 18 December 2024.
- Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, Article 2.
This article is a working guide for English-speaking readers and does not constitute legal advice. The binding texts are the German, French and Italian ones.